2023-03-17 | NRP-38Added · Updated
The Standards Committee of the Central Reserve Bank of El Salvador issued these standards to regulate access to and use of the Debtor Inquiry System administered by the Superintendence of the Financial System. The document mandates that supervised financial entities, including banks, cooperatives, and insurance companies, designate a liaison executive and authorized users who must submit notarized commitment letters and risk management manuals. Access credentials are assigned within eight business days, and entities must notify the Superintendence of user changes within five business days while maintaining strict confidentiality of debtor information. Existing users must submit updated commitment letters within thirty business days of the April 3, 2023 effective date, and existing system users must submit risk management manuals within sixty business days.
Alameda Juan Pablo II, between 15 and 17 Av. Norte, San Salvador, El Salvador. Tel. (503) 2281-8000 www.bcr.gob.sv Page 1 of 12 CNBCR-02/2023 NRP-38 TECHNICAL STANDARDS FOR ACCESS AND USE OF THE DEBTOR INQUIRY SYSTEM Approval: 17/03/2023 Validity: 3/04/2023
THE STANDARDS COMMITTEE OF THE CENTRAL RESERVE BANK OF EL SALVADOR,
CONSIDERING:
I. That Article 61 of the Banks Law establishes that the Superintendence shall maintain a credit information service regarding users of the institutions that are part of the financial system, with the objective of facilitating the evaluation of risks of their operations, and that banks and other institutions supervised by the Superintendence of the Financial System shall be obligated to provide the information required by the same.
II. That Article 39 of the Law on Cooperative Banks and Savings and Credit Societies establishes that cooperatives shall be obligated to provide the information that the Superintendence requires to maintain its credit information system; likewise, they shall have the right to use the aforementioned credit information service.
III. That Article 71 of the Investment Banks Law establishes that what is established in Article 61 of the Banks Law shall apply to Investment Banks, among others, insofar as it does not contravene the Investment Banks Law, nor the nature or purpose of Investment Banks. (1)
IV. That Article 3 literal c) of the Law on Supervision and Regulation of the Financial System establishes that it is the responsibility of the Superintendence of the Financial System to monitor preventively the risks of the members of the financial system and the manner in which they manage them, ensuring the prudent maintenance of their solvency and liquidity. (1)
V. That Article 35, first paragraph, literal d) of the Law on Supervision and Regulation of the Financial System establishes that directors, managers, and other officials holding positions of direction or administration of the members of the financial system must conduct their business, acts, and operations complying with the highest ethical standards of conduct, acting with the due diligence of a good merchant in their own business, being obligated to comply with and ensure that in the institution they direct or work for, the adoption and updating of policies and mechanisms for risk management are fulfilled, among other actions, identifying, evaluating, mitigating, and revealing them in accordance with international best practices. (1)
VI. That Article 99, third paragraph, literal a) of the Law on Supervision and Regulation of the Financial System establishes that it corresponds to the Standards Committee of the Central Reserve Bank of El Salvador the approval of technical standards on any other aspect inherent to risk management by the supervised entities. (1)
Alameda Juan Pablo II, between 15 and 17 Av. Norte, San Salvador, El Salvador. Tel. (503) 2281-8000 www.bcr.gob.sv Page 2 of 12 CNBCR-02/2023 NRP-38 TECHNICAL STANDARDS FOR ACCESS AND USE OF THE DEBTOR INQUIRY SYSTEM Approval: 17/03/2023 Validity: 3/04/2023
VII. That it is necessary to have an updated regulatory framework in accordance with current legislation so that entities of the financial system can make inquiries to the debtor information of the Risk Central administered by the Superintendence of the Financial System. (1)
THEREFORE,
in virtue of the regulatory powers conferred by Article 99 of the Law on Supervision and Regulation of the Financial System,
AGREES to issue the following:
TECHNICAL STANDARDS FOR ACCESS AND USE OF THE DEBTOR INQUIRY SYSTEM
CHAPTER I OBJECTIVE, SUBJECTS, AND TERMS
Objective Art. 1.- These Standards aim to establish guidelines for access to and use of the Debtor Inquiry System that the Superintendence of the Financial System has made available to the entities of the financial system.
Subjects Art. 2.- The subjects obligated to comply with the provisions established in these Standards are: a) Cooperative Associations providing insurance services constituted in the country; b) Banks constituted in El Salvador; c) Cooperative Banks; d) Investment Banks; (1) e) Entities subject to the supervision, inspection, and surveillance of the Superintendence of the Financial System that have within their activity the granting of credits and have requested the creation of access keys for the consultation of the referred System; (1) f) Federations of Cooperative Banks; (1) g) Fund for Financial Sanitation and Strengthening; (1) h) Official Credit Institutions; (1) i) Insurance Companies constituted in El Salvador; (1) j) Savings and Credit Societies; (1) k) Reciprocal Guarantee Societies; (1) l) Branches of foreign banks authorized and established in El Salvador; (1) m) Subsidiaries of controlling banks or holding companies of exclusive purpose constituted in El Salvador; (1) and
Alameda Juan Pablo II, between 15 and 17 Av. Norte, San Salvador, El Salvador. Tel. (503) 2281-8000 www.bcr.gob.sv Page 3 of 12 CNBCR-02/2023 NRP-38 TECHNICAL STANDARDS FOR ACCESS AND USE OF THE DEBTOR INQUIRY SYSTEM Approval: 17/03/2023 Validity: 3/04/2023
n) Branches of foreign insurance companies authorized and established in El Salvador. (1)
Terms Art. 3.- For the purposes of these Standards, the terms indicated below have the following meaning: a) Central Bank: Central Reserve Bank of El Salvador; b) Automatic Query: Queries performed through a software program or online, by one or more users, for the financial entity to access and use the automated consultation of the debtor system. The financial entity must comply with the security protocols defined by the Superintendence of the Financial System; c) Manual Query: Queries performed through human action by means of authorized users for access and manual use of the Debtor Inquiry System; d) Debtor(s): Person(s) who have one or more credits in the entities of the financial system, either directly, as a principal debtor, or indirectly as a co-debtor or guarantor; e) Liaison Executive: Person in charge of coordination with the Superintendence for the management of access, modification, and deactivation of users of the Debtor Inquiry System; f) Entity/entities: Subjects obligated to whom Article 2 of these Standards refers; g) Debtor Information: Information regarding the behavior of Debtors of the Financial System in their various credit obligations, which contributes to facilitating the evaluation of risks thereof; h) System or Inquiry System: Debtor inquiry system that the Superintendence has made available to the entities; i) Superintendence: Superintendence of the Financial System; and j) User: Person who has the corresponding permissions for access to and use of the Debtor Inquiry System, authorized to perform queries either in manual or automatic mode, of which they will be the direct responsible party.
CHAPTER II OF THE ACCESS OF ENTITIES TO THE DEBTOR INQUIRY SYSTEM
Of the System Art. 4.- The Superintendence, through the Debtor Inquiry System, will provide entities with agile access to useful information for the evaluation of credit risks of debtors of the financial system.
Of access to the System Art. 5.- The entity interested in having access to the Debtor Inquiry System must send to the Superintendence a Commitment Letter signed by its president or Legal Representative, authenticated before a Notary, in accordance with the model of Annex No. 1 of these Standards, in which said entity commits to handle the information obtained from the System confidentially, as well as to adequately use the users and passwords assigned by the Superintendence. Additionally, the entity must present attached to the Commitment Letter, the designation of the person who will perform the role of liaison executive, identifying the holder and their substitute, sending to the Superintendence their respective Commitment Letters and other requirements established in the literals of Article 8 of these Standards.
Liaison Executive Art. 6.- The entity, through its president, legal representative, or proxy with sufficient powers, must designate a liaison executive and their substitute, who will be in charge of direct communication and coordination with the Superintendence, and will be responsible for requesting access keys to the System, as well as keeping control of active users, whether automatic or manual mode, and informing about users who must be deactivated from the System due to transfer or separation. The person performing the functions of liaison executive must preferably hold a position of direction, management, or equivalent in the risk, business, or similar area in the entity, in addition to having worked for it for more than six months.
CHAPTER III OF THE USERS OF THE DEBTOR SYSTEM
Of the users Art. 7.- The entity may access the inquiry system through users, to whom access credentials will be assigned, for the purpose of performing queries of debtor information, for their respective credit evaluation. The person designated as a user may perform queries according to the modality authorized, that is, manual and/or automatic, and will also be the direct responsible party for said queries. In any case, it must be verified that the queries performed comply with the policies and risk manuals associated with the use of the System, in accordance with what is established in Chapter V of these Standards, ensuring the safeguarding and confidentiality of the information accessed. Users must work in risk management, commercial, business, or similar areas, in addition to having worked for the entity for at least three months or having previously worked in similar positions or having held these same accesses in other entities.
Alameda Juan Pablo II, between 15 and 17 Av. Norte, San Salvador, El Salvador. Tel. (503) 2281-8000 www.bcr.gob.sv Page 4 of 12 CNBCR-02/2023 NRP-38 TECHNICAL STANDARDS FOR ACCESS AND USE OF THE DEBTOR INQUIRY SYSTEM Approval: 17/03/2023 Validity: 3/04/2023
Of the user request Art. 8.- The entity requiring the creation of a new user will send to the Superintendence the request signed by the liaison executive, attaching the following documentation: a) Commitment Letter signed by the user, in accordance with Annex No. 2 of these Standards; b) Certificate issued by the Head of Human Management or similar, of the entity, mentioning the position and entry date of the employee for whom access is being requested; c) Description of the current position, signed and stamped by the Human Resources department, according to the Job Manual, where the activities of the position held by the designated employee are evidenced; and d) User information table in accordance with Annex No. 3 of these Standards.
Assignment of keys Art. 9.- Upon receipt of the request and the documentation established in Article 8 of these Standards, the Superintendence will assign to the entity the codes and access keys of the user(s) requested through the liaison executive, in accordance with the request and documentation established in Article 8 of these Standards (1). The sending of the access codes and keys must be done no later than within a period of eight business days from the date on which the request documents have been received complete and in due form.
Change or addition of users Art. 10.- The entity requiring a change of users must send through the liaison executive, the corresponding request accompanied by the documentation referred to in Article 8 of these Standards as applicable, in addition to the detail of the users to be deactivated. In case the entity requires additional users, the liaison executive must send the request in accordance with what is established in Article 8 of these Standards, which must contain the justification of the request.
CHAPTER IV RESPONSIBILITIES AND HANDLING OF INFORMATION OF THE ENTITY USERS OF THE DEBTOR SYSTEM
Responsibilities of entities for access to the Debtor System Art. 11.- With regard to the use of the System, the entity must comply with the following: a) Establish security conditions in the computer equipment on which access and use of the debtor system is performed; b) Inform in writing to the Superintendence, no later than five business days after any of its employees designated, both as responsible or liaison executive, has been removed due to separation from their position, transfer, or any other circumstances; and c) Respond for the non-compliance that System users make to the regulations established in these Standards, and in the policies and risk manuals associated with their use.
Of the responsibilities of users Art. 12.- With regard to the use of the System, users must comply with the following: a) Whenever access to the System is required, persons authorized through a user to perform manual queries must type their username and access key, abstaining from configuring on the electronic device they use, the function of reminder of users and keys; b) Persons authorized to access the System through a user to perform manual queries must safeguard confidentially the user codes and access keys assigned to them; consequently, said means will only be used by said persons; c) For manual queries, user codes and keys will be for exclusive use of the employees requested by the liaison executive; therefore, they must not be transferred or shared with any other person or with an entity different from the one that requested them; d) For automatic queries, they must guarantee the security of access and use in the resources or activities that automate the queries to be performed. Likewise, the codes and keys of users authorized to perform automatic queries cannot be used for purposes other than those for which they were created, nor can they be transferred or shared with an entity different from the one that requested them; e) Adequate handling, control, and follow-up of the queries performed under the code authorized to them must be ensured, in accordance with the entity's information security policies; and f) Comply at all times with the policies and risk manuals associated with the use of the System.
Handling of information Art. 13.- The information contained in the System is considered reserved, for which reason, the entity must handle it as such and attend to at least the following: a) The information must be known and used only by the entity with the sole purpose of facilitating the risk evaluation of its credit operations; b) Safeguard the confidentiality of the information, as well as contemplate the security measures of the users and personnel who have access to the information of the referred System; c) The information from the System's databases that the Superintendence provides to entities must not be used to create other databases for the search of potential clients, except when it concerns information related to received credit requests; d) No entity or person, free of charge or for consideration, must transfer the information received from the System; and e) Reports generated by the System regarding the rating of debtors are confidential, therefore, they cannot be public domain, but only of the using entity.
Of the communication with the Superintendence Art. 14.- Communication between the entity and the Superintendence on topics related to the Debtor Inquiry System must be channeled exclusively through the liaison executive or their substitute.
CHAPTER V OF THE RISK MANAGEMENT OF THE ENTITY USERS OF THE DEBTOR INQUIRY SYSTEM
Of the policies and risk management manual Art. 15.- The entity using the Debtor Inquiry System must approve and implement the policies and risk management manuals associated with the use of the System by its users, in accordance with what is established in Chapters II and IV of the Technical Standards for Integral Risk Management of Financial Entities (NRP-20), in order to monitor preventively the risks associated with the use of the System and guarantee the confidentiality of the information of the consulted debtors.
Of the submission of the policies and risk management manual Art. 16.- The entity, prior to having access to the inquiry System, must send to the Superintendence, by the means it defines, the policies and risk management manual authorized by the corresponding body, in accordance with what is established in Article 15 of these Standards.
CHAPTER VI OTHER PROVISIONS AND VALIDITY
Supervision of the use of the System Art. 17.- The Superintendence will conduct audits periodically in the entities, to verify the good use of the System, for which the audited entity must provide the information and documents necessary to the delegate of the Superintendence. If as a result of the audit it is determined that any of the users has infringed any of the provisions contained in these Standards, the Superintendence will make the entity aware of said situation and will proceed to suspend the access to the System by the infringing user, without prejudice to the legal actions that may arise and it will only be restored, until it is proven that the entity has remedied the deficiencies that caused the infractions.
Alameda Juan Pablo II, between 15 and 17 Av. Norte, San Salvador, El Salvador. Tel. (503) 2281-8000 www.bcr.gob.sv Page 5 of 12 CNBCR-02/2023 NRP-38 TECHNICAL STANDARDS FOR ACCESS AND USE OF THE DEBTOR INQUIRY SYSTEM Approval: 17/03/2023 Validity: 3/04/2023
Art. 18.- Once the entity has remedied the deficiencies that gave rise to the suspension of access to the System, the liaison executive must present the request to the Superintendence so that they are enabled again to access the System or attending to what is established in Article 9 of these Standards, as applicable.
Users and liaison executives authorized before validity Art. 19.- The System users, who prior to the date of entry into force of these Standards, the Superintendence had authorized user codes and access keys to access the System, may continue using them for such purposes; nevertheless, the entity within a maximum period of thirty business days after the entry into force of these Standards must send to the Superintendence the Commitment Letter of each of the users, according to the model contained in Annex No. 2 of these Standards. This provision will be applicable to the liaison executives. The entity that on the date of entry into force of these Standards has access to the debtor inquiry system will be exempt from presenting the Commitment Letter established in Annex No. 1 of these Standards.
Sanctions Art. 20.- Non-compliance with the provisions contained in these Standards will be sanctioned in accordance with what is established in the Law on Supervision and Regulation of the Financial System.
Derogation Art. 21.- These Standards derogate the "Standards for the Use of the Internet Debtor Inquiry System of the Risk Central" (NPB4-40), approved in Session No. 18/2009 of May 6, 2009 by the Board of Directors of the Superintendence of the Financial System, whose Organic Law was derogated by Legislative Decree number 592 which contains the Law on Supervision and Regulation of the Financial System, published in the Official Diary No. 23, Volume No. 390, of date February 2, 2011.
Transitory Art. 22.- The entities that on the date of entry into force of these Standards already have access to the Inquiry System must send within a period of sixty business days after the entry into force of these, the policies and risk management manual authorized by the corresponding body, in accordance with what is established in Article 15 of these Standards.
Alameda Juan Pablo II, between 15 and 17 Av. Norte, San Salvador, El Salvador. Tel. (503) 2281-8000 www.bcr.gob.sv Page 6 of 12 CNBCR-02/2023 NRP-38 TECHNICAL STANDARDS FOR ACCESS AND USE OF THE DEBTOR INQUIRY SYSTEM Approval: 17/03/2023 Validity: 3/04/2023
Unforeseen Aspects Art. 23.- The aspects not provided for in regulatory matters in these Standards will be resolved by the Central Bank through its Standards Committee.
Validity Art. 24.- These Standards will enter into force from the third of April of two thousand twenty-three.
MODIFICATIONS:
(1) Modifications in Considerations III, IV, V, and VI, and incorporation of Consideration VII, modifications in Articles 2 and 9, and in Annexes Nos. 1 and 2, approved by the Standards Committee of the Central Reserve Bank of El Salvador, in Session No. CN-09/2025, of November 10, two thousand twenty-five, with validity from the day of November 25, two thousand twenty-five.
Alameda Juan Pablo II, between 15 and 17 Av. Norte, San Salvador, El Salvador. Tel. (503) 2281-8000 www.bcr.gob.sv Page 7 of 12 CNBCR-02/2023 NRP-38 TECHNICAL STANDARDS FOR ACCESS AND USE OF THE DEBTOR INQUIRY SYSTEM Approval: 17/03/2023 Validity: 3/04/2023
Annex No. 1
ENTITY COMMITMENT LETTER In the city of San Salvador, at ____